Thread (12 messages) flat view 12 messages, 3 authors, 2016-10-29

Re: [PATCH net 2/3] sctp: return back transport in __sctp_rcv_init_lookup

From: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Date: 2016-10-28 21:39:53
Also in: linux-sctp

On Fri, Oct 28, 2016 at 05:42:21PM -0200, Marcelo Ricardo Leitner wrote:
On Fri, Oct 28, 2016 at 06:10:53PM +0800, Xin Long wrote:
quoted
Prior to this patch, it used a local variable to save the transport that is
looked up by __sctp_lookup_association(), and didn't return it back. But in
sctp_rcv, it is used to initialize chunk->transport. So when hitting this
code, it was initializing chunk->transport with some random stack value
instead.

This patch is to return the transport back through transport pointer
that is from __sctp_rcv_lookup_harder().

Signed-off-by: Xin Long <lucien.xin@gmail.com>
Acked-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>

transport pointer in sctp_rcv() is initialized to null and there are
checks for it after this path, so this shouldn't be exploitable, just
malfunction.
This actually sort of contradicts the changelog.

Xin, did I miss something here? Seems we need to update the changelog if
not.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help